Medium severity4.4NVD Advisory· Published Sep 29, 2026
CVE-2026-102877
CVE-2026-102877
Description
Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.gonvd
- github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.gonvd
- github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69nvd
- github.com/getfider/fider/releases/tag/v0.38.0nvd
- github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjhnvd
- www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validationnvd
News mentions
0No linked articles in our index yet.